Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1322227

Summary: openstack-swift: Fix for CVE-2015-5223 is partially present in openstack-swift-2.3.0-5.el7ost build
Product: Red Hat OpenStack Reporter: Prashanth Pai <ppai>
Component: openstack-swiftAssignee: Pete Zaitcev <zaitcev>
Status: CLOSED ERRATA QA Contact: Mike Abrams <mabrams>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 7.0 (Kilo)CC: cschwede, derekh, jschluet, mabrams, nlevinki, srevivo, zaitcev
Target Milestone: asyncKeywords: ZStream
Target Release: 7.0 (Kilo)   
Hardware: All   
OS: All   
Whiteboard:
Fixed In Version: openstack-swift-2.3.0-6 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-10-05 19:15:48 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1263018    
Bug Blocks:    

Description Prashanth Pai 2016-03-30 05:18:35 UTC
Description of problem:

The complete fix for CVE-2015-5223 is comprised of two separate upstream commits: 410778b86a49702f80b734bdbf2480b86db342e2 and f81435d340140a0b54ac555870423894ee9b2131

openstack-swift-2.3.0-5.el7ost build in brew contains only one of the commits i.e: 410778b86a49702f80b734bdbf2480b86db342e2


Version-Release number of selected component (if applicable):
openstack-swift-2.3.0-5.el7ost


How reproducible:
This was discovered when upstream test suite from stable/kilo branch was being run against a downstream build i.e openstack-swift-2.3.0-5.el7ost
Tests pertaining to CVE-2015-5223 failed.


Actual results:
openstack-swift build contains partial fix.


Expected results:
openstack-swift build must contain both the commits i.e the complete fix.

Comment 15 nlevinki 2016-10-05 10:34:13 UTC
Automation passed
https://rhos-jenkins.rhev-ci-vms.eng.rdu2.redhat.com/view/RHOS/view/RHOS7/job/qe-7_director-rhel-7.2-virthost-1cont_1comp_1ceph-ipv4-vxlan-ceph-ssl/3/
verified with this rpm
openstack-swift-container-2.3.0-7.el7ost.noarch

Comment 17 errata-xmlrpc 2016-10-05 19:15:48 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2028.html

Comment 18 Red Hat Bugzilla 2023-09-14 03:20:19 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days